Update X.Org Server 1.20.11 addressing the vulnerability

The release of X.Org Server 1.20.11 has been published, which fixes a vulnerability (CVE-2021-3472) that allows privilege escalation in systems where the X server runs with root rights. The issue stems from a flaw in the XInput extension that causes the modification of memory content outside of the allocated buffer while processing ChangeFeedbackControl requests with specially crafted input. A similar issue has also been fixed in component xwayland 21.1.1.

In addition to fixing the vulnerability in X.Org Server 1.20.11, work has also been done to clean up the DDX component of XQuartz, used to run X11 applications in a macOS environment. The new version has removed the ability to build XQuartz for i386 systems and ended support for macOS versions 10.3 'Panther', 10.4 'Tiger', 10.5 'Leopard', 10.6 'Snow Leopard', 10.7 'Lion', and 10.8 'Mountain Lion'.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster